Thread (8 messages) 8 messages, 3 authors, 13d ago

Re: [PATCH v2 net 0/3] ipv4/ipv6: Fix UAF and memory leak in IGMP/MLD

From: patchwork-bot+netdevbpf@kernel.org
Date: 2026-07-08 12:50:30

Hello:

This series was applied to netdev/net.git (main)
by Paolo Abeni [off-list ref]:

On Sun,  5 Jul 2026 18:17:53 +0000 you wrote:
This series addresses two potential UAF vulnerabilities
and memory leaks in the IPv4 IGMP and IPv6 MLD subsystems.

The first two patches fix a UAF where the packet receive path races with
device teardown. If the device refcount has already hit 0 (but the memory
is still held by RCU), incoming IGMP/MLD packets trying to schedule delayed
work or timers would call refcount_inc() on the 0 refcount, triggering a
warning and eventually leading to a UAF when the work runs after the device
has been freed. This is fixed by introducing safe hold helpers using
refcount_inc_not_zero(). In MLD, we also ensure we only enqueue the skb
if we successfully acquired the device reference, to avoid leaking skbs
when the device is being destroyed.

[...]
Here is the summary with links:
  - [v2,net,1/3] ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
    https://git.kernel.org/netdev/net/c/7b19c0f81ed1
  - [v2,net,2/3] ipv6: mcast: Fix potential UAF in MLD delayed work
    https://git.kernel.org/netdev/net/c/9b26518b6896
  - [v2,net,3/3] ipv4: igmp: Fix potential memory leaks in igmp_mod_timer() and igmp_stop_timer()
    https://git.kernel.org/netdev/net/c/3546deaa0c30

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help